Paper-craft illustration: a navy document labelled AI DRAFT, a burnt-orange checkpoint gate labelled HUMAN CHECK with a cream tick beneath it, and a navy outbox tray labelled LIVE — a dashed orange line runs through the gate before reaching the tray.

Guide

The AI Guardrail Playbook: Checklists, Review Gates, and Rules Your Team Will Actually Use

Not a 40-page policy nobody reads — a one-page playbook, three review tiers, and a 90-second checklist that sits between “AI drafted this” and “this is now live.”

AI will draft your emails, summarise your contracts, and answer your customers before a human ever sees the output, if you let it. That’s the point. The trouble starts when nobody checks the output before it goes out the door.

In February 2024, a tribunal in British Columbia found Air Canada liable for a refund policy its own chatbot made up on the spot.[1] In 2025, Deloitte had to repay part of a AU$440,000 government contract after a researcher found fabricated references in a report built with AI assistance.[2] Neither company set out to ship a mistake. Neither had a human check the output before a customer, or a government department, saw it.

None of this is an argument against using AI. LOKAL runs on it. Since 2017 we’ve trained more than 5,000 people across the Philippines and Australia, and in one 4,000-person rollout, 72% were using AI weekly within a month. What we’re arguing for is small and concrete: a few checkpoints between “AI drafted this” and “this is now live.” Not a policy binder nobody reads but a playbook your team will actually reach for.

5,000+ people trained on practical AI across the Philippines and Australia since 2017
4,000 staff in one enterprise rollout we ran end to end
72% of them using AI weekly within 30 days
1 page the length of a guardrail document people actually read

What a guardrail actually is

A guardrail is not a 40-page AI acceptable-use policy sitting in a shared drive. It’s a specific rule that limits what AI can do without a person checking first. Useful guardrails read like this:

  • AI can draft a client email. A human sends it.
  • AI can summarise a contract. A human confirms anything that changes price, liability, or scope.
  • AI can propose social copy. A human approves anything naming a competitor, a client, or a number.
  • AI can answer common customer questions. A human reviews anything about refunds, pricing exceptions, or complaints.

That’s four rules, not a framework. Most small and mid-sized businesses need somewhere between five and fifteen of these, organised by where the risk actually sits and not a governance committee.

Guardrails are the second half of a pair. The first half is deciding what to hand over at all — which is the job of our Create, Understand, Act framework. Sort the task first, then set the checkpoint.

The three places AI mistakes ship

Nearly every public AI failure falls into one of three buckets. Knowing which bucket you’re exposed in tells you where to put your first guardrail.

Paper-craft illustration: three navy circular medallions joined by dashed orange lines — one holding a speech bubble with a pen nib, one holding a padlock over a document, one holding a set of balance scales.
Content and brand, data and privacy, decision and legal — three buckets, three different failure modes.

1. Content and brand risk

AI writes something inaccurate, off-tone, or defamatory, and it goes out under your name. A blog post, a social caption, a client report. This is where hallucinated facts and fabricated citations live. It’s also the least dramatic-looking risk and the easiest to skip checking, which is exactly why it catches people out.

2. Data and privacy risk

A staff member pastes something they shouldn’t into a public AI tool. Customer records, financial figures, unreleased pricing, another client’s brief. Samsung’s engineers famously pasted proprietary source code into ChatGPT to help debug it; the data was gone the moment they hit enter.[3] This risk is invisible until it isn’t.

3. Decision and legal risk

AI’s output gets treated as fact in a document with real consequences. A legal brief, a compliance report, a customer commitment. This is the bucket that produced the Air Canada tribunal ruling and Deloitte’s repayment. It’s also the bucket where courts have now fined lawyers individually. In one March 2026 case, two attorneys were fined $15,000 each, plus the other side’s legal fees, for filing briefs with more than two dozen fabricated citations between them.[4]

Map your own AI use against these three before you write a single rule. Most businesses are more exposed in one bucket than the other two.

The one-page AI guardrail template

You don’t need a governance framework. You need one page, six sections, that a new hire can read in five minutes:

  1. 01

    Stance

    One sentence on how your business treats AI. For example: “AI drafts, humans decide and publish.”

  2. 02

    Approved tools

    Which AI tools staff can use for work, and on what account (never a personal login for company work).

  3. 03

    Data rules

    What can never go into a prompt — customer PII, financial data, unreleased material, anything under NDA — versus what’s fine: public information, general drafting, formatting help.

  4. 04

    Human review points

    The specific moments a person must check AI output before it moves forward (see the review gates below).

  5. 05

    Disclosure

    Where and when you tell clients or customers that AI was involved, even briefly.

  6. 06

    Ownership

    Who owns this document, who can update it, and how often it gets reviewed.

Print it, pin it in your team wiki, put it on page one of onboarding because a guardrail nobody has read is not a guardrail at all.

Review gates: a three-tier system

Not every piece of AI output carries the same risk, so not everything needs the same level of scrutiny. A simple three-tier system keeps this fast instead of bureaucratic:

Tier What it covers Who checks it
Tier 1 — Low stakes, light check Internal drafts, brainstorm lists, first-pass summaries One person skims for obvious errors before anyone relies on it. No sign-off required.
Tier 2 — Customer- or public-facing Blog posts, social captions, marketing emails, internal reports shared with a manager A named reviewer checks facts, tone, and brand voice against the checklist below before it publishes.
Tier 3 — Legal, financial or reputational exposure Anything quoting a price, making a promise, citing a source, going to a regulator, or representing the business externally at scale Two people: one for accuracy, one for the actual decision to publish or send. No exceptions.
Paper-craft illustration: three navy paper steps rising left to right, with one cream tick on the lowest, two on the middle, and two ticks plus a burnt-orange wax seal on the highest — a dashed orange line climbing over them.
Scrutiny should climb with exposure — one check, two checks, two checks and a named sign-off.

Most businesses make the same mistake: they apply Tier 1 scrutiny to Tier 3 content because the AI output “looked confident.” But confidence isn’t accuracy. The 2023 case that started the legal profession’s AI reckoning proves it. A New York lawyer filed a ChatGPT-drafted brief citing six cases that didn’t exist,[5] and it happened for one reason: the writing looked polished enough that nobody thought to check.

Polish is not proof. Treat confident-sounding output as unverified until someone has actually checked it.

The pre-publish QC checklist

Before anything Tier 2 or Tier 3 goes live, run it through these checks. Ninety seconds, most of the time.

Paper-craft illustration: a cream clipboard holding a checklist ticked with burnt-orange marks, a cream magnifying glass hovering over one line, and a navy stamp pressing an orange seal at the foot of the page.
Eight checks, ninety seconds — then a named human stamps it.

This is the same discipline LOKAL teaches inside its own practical AI skills training: AI is a co-pilot, not an autopilot. It drafts; a person checks the numbers, verifies the facts, and reviews the tone before anything ships.

Data-handling rules for staff

Keep this part plain-language, because vague rules get ignored and specific ones get followed.

Never paste into a public AI tool Generally safe
Customer personal information Public information
Financial data General work questions
Passwords or access credentials Drafting help and formatting
Unreleased pricing or product details Brainstorming
Anything covered by an NDA Summarising documents already meant to be shared
Another client’s confidential brief

Where a human must never be skipped

Regardless of tooling, four things always need a person, no shortcuts:

  • Anything that commits the business — a price, a refund, a deadline, a guarantee, a contract term.
  • Anything published externally under your name — blog content, press statements, client reports, social posts.
  • Anything citing a source, case, statistic or quote — verify it exists and says what it’s claimed to say.
  • Anything touching customer or employee personal data — a privacy review before it’s processed, not after.

This holds even as the tooling gets more capable. Agents that can reach your calendar, drive and CRM widen what “AI did it” covers — worth understanding before you set the rules, which is what our plain-English guide to agents, MCP and Skills is for.

Rolling this out without creating compliance theatre

A guardrail system fails the same way an AI pilot fails: it looks good in the launch meeting and nobody follows it three months later. Treat the rollout the way you’d treat any change management project such as assigning an owner, training the team on the actual document (not just an email announcing it), and checking back at 30, 60, and 90 days to see whether the review gates are actually being used or quietly skipped. That’s the same adoption discipline behind LOKAL’s own AI adoption and implementation work. The guardrails only count if people are still using them after the first month.

Sources

  1. Moffatt v. Air Canada, 2024 BCCRT 149 (B.C. Civil Resolution Tribunal, Feb. 14, 2024). canlii.org
  2. “Deloitte to refund government after using AI in $440k report,” Accounting Times, Oct. 9, 2025 — on the Department of Employment and Workplace Relations report, its fabricated academic references and misquoted Federal Court orders. accountingtimes.com.au (also reported by CFO Dive)
  3. “Samsung Bans ChatGPT Among Employees After Sensitive Code Leak,” Forbes, May 2, 2023. forbes.com
  4. Whiting v. City of Athens (6th Cir., March 2026); “Sixth Circuit Slaps Steep Sanctions on Two Lawyers for Fake Citations and Misrepresentations in Appellate Briefs,” LawSites, March 2026. lawnext.com
  5. Mata v. Avianca, Inc., No. 1:22-cv-01461, sanctions opinion (S.D.N.Y. June 22, 2023). law.justia.com

Every citation above was checked against its source before this piece was published — the same check the article asks you to run.

FAQ

Common questions

What is an AI guardrail, in plain terms?

A specific rule that limits what AI can do without a person checking first — for example, “AI can draft a client email, but a human sends it.”

Do we need a written AI policy if we’re a small team?

Yes, but it doesn’t need to be long. One page covering your stance, approved tools, data rules, review points, disclosure practice, and document ownership covers most small teams.

Who should have final sign-off on AI-generated content or decisions?

A named person, not “the team.” For anything Tier 2 or higher, one person checks accuracy and a second confirms the decision to publish or send — especially for anything that commits the business.

How do we check for AI hallucinations before publishing?

Verify every name, number, date, quote, and citation against a real, checkable source. Treat confident-sounding output as unverified until someone has actually checked it — polish is not proof.

What data should staff never paste into an AI tool?

Customer personal information, financial figures, passwords or access credentials, unreleased pricing, NDA-covered material, and anything belonging to another client.

Done-for-you

Want guardrails your team will actually use?

We build the governance and operating model — permissions, risk tiers, data-handling rules and review cadence — then wire it into the workflows you already run and train your team on it. The same system behind a 4,000-person rollout that hit 72% weekly use in 30 days.